GHSA-9jjc-fw8x-fmwx: io.moquette:moquette-broker has a Missing Authorization issue
HIGHHigh-risk vulnerability — CVSS 7.5
## Summary Moquette MQTT Broker fails to enforce ACL write permission checks when publishing Will (Last Will and Testament) messages on behalf of disconnected clients. All normal PUBLISH paths (`receivedPublishQos0`, `receivedPublishQos1`, `receivedPublishQos2`) correctly invoke `authorizator.canWrite()` before publishing, but the Will message publishing path (`fireWill()` → `publishWill()` → `publish2Subscribers()`) completely bypasses this authorization check. …
CVE · detail
- CVE-2026-85058nvd ↗EPSS 0.45%
● loading threat intel…
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected